Quick start
This sets up a DeaconGuard server, enrolls one machine and scans it. You need two Linux machines running a supported distribution with systemd, and an account that can use sudo.
1. Install the server
On the machine that will host the dashboard:
curl -fsSL https://get.deaconguard.io | sh -
The script checks and installs the package, then asks you for the first dashboard account. The password needs at least 12 characters. When it finishes it prints the dashboard's addresses and the server certificate's fingerprint:
The DeaconGuard server is running. Open the dashboard and sign in:
https://dg-server:8443
https://203.0.113.10:8443
Certificate public key (SHA-256): 5Qf7450fYjqub77irpmvRGyNK-HhiYE-GCAEBIYleEs
Open one of the addresses and sign in. The server uses a self-signed certificate, so your browser warns about it once; check that the fingerprint matches before you continue.
Only allow port 8443 from the networks your administrators and agents are in.
2. Enroll a machine
-
In the dashboard, open Agents and click Enroll a machine.
-
Check the address agents will use to reach the server, then click Create token.
-
Copy the command the dialog shows and run it on the machine you want to scan:
curl -fsSL https://get.deaconguard.io | DEACONGUARD_TOKEN=deaconguard1.… sh -
The machine appears on the Agents and Hosts pages within a few seconds. The token works once and expires after 24 hours.
3. Scan it
Open the machine on the Hosts page and click Scan now. Choose the checks you want; Package vulnerabilities is the default. The page shows a live console while the scan runs, and the full report when it finishes.